Privacy Policy

Last updated: July 13, 2026

RECENSIO LIMITED — a private company limited by shares, incorporated in Ireland Company registration number (CRO): 820098 Registered office: Unit 2, 2 Bridge Street, Athlone, Co. Westmeath, N37 F1W4, Ireland Data protection contact: support@recensio.ai

This is the original English-language version of this Privacy Policy. Translations are provided for convenience. In the event of any conflict or inconsistency between the English version and a translation, the English version prevails.


1. About this Privacy Policy

This Privacy Policy explains how RECENSIO LIMITED ("Recensio", "we", "us", "our") collects and processes personal data in connection with the Recensio service (the "Service"), our website at recensio.ai (the "Website"), and our related communications.

Recensio is a software-as-a-service tool that helps businesses manage and respond to their Google reviews. Our customers are businesses (for example restaurants, hotels, shops, professional practices and marketing agencies). The Service analyses each review, drafts a reply in the business's tone of voice, and — depending on the customer's automation settings — either submits it for the customer's approval or approves it automatically; once approved, the reply is published to the customer's Google Business Profile on the customer's behalf.

We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR"), the Irish Data Protection Act 2018, and other applicable law.


2. Our two roles: controller and processor

Understanding which role we play matters, because it determines who is responsible for the data.

We are the data controller for personal data relating to our own relationship with our customers and website users — namely account and subscription data, billing data, agency contact data, waitlist data, and data about visitors to our Website. For this data we decide why and how it is processed, and this Privacy Policy is our notice to you.

We are a data processor for the review content that our customers process through the Service — namely the Google reviews of the customer's business, the names of the reviewers, the profiling of reviewers described in Section 7, and the replies generated. For this data the customer is the controller: the customer decides the purposes and means, and we act only on the customer's documented instructions under a data processing agreement that meets Article 28 GDPR. We never use this review data for our own purposes — no cross-customer analytics, no sale, and no use to train any artificial-intelligence model. This restriction is a binding condition of the Service.

If you are the subject of a review and wish to exercise your rights over review content, the controller is the business that owns the review. We will assist that business as its processor.


3. Personal data we process as controller

3.1 Account and subscription data

When you create an account or subscribe, we process your email address, your name, your chosen interface language and, where you provide it, a contact telephone/WhatsApp number. For customers on our Agency plan we also process the agency name and the agency's contact email and telephone number, and the contact details you enter for the businesses you manage (contact name, contact email, contact telephone) together with any internal notes you choose to record about those businesses.

Purpose: to create and administer your account, provide the Service, and support you. Legal basis: performance of our contract with you (Article 6(1)(b) GDPR); for internal notes and agency contact details, our and our customer's legitimate interest in operating the Service (Article 6(1)(f) GDPR).

3.2 Billing data

We process billing information through our payments provider, Stripe. In our own systems we store the Stripe customer and subscription identifiers that link to your payment record; card and bank details are handled by Stripe and are not stored on our servers.

Purpose: to take payment, manage your subscription, and keep the accounting records the law requires. Legal basis: performance of our contract (Article 6(1)(b) GDPR) and compliance with our legal obligations, including tax and accounting law (Article 6(1)(c) GDPR).

3.3 Waitlist data

If you join our waitlist, we process your email address and the IP address from which you signed up.

Purpose: to contact you about availability of the Service, and to prevent abuse and spam of the sign-up form. Legal basis: your consent for the waitlist contact (Article 6(1)(a) GDPR); our legitimate interest in preventing abuse for the IP address (Article 6(1)(f) GDPR).

3.4 Feedback you submit

If you submit free-text feedback through the Service (for example through an experience page), we process the content you provide, which may contain personal data if you choose to include it.

Purpose: to receive and act on your feedback. Legal basis: our legitimate interest in improving the Service (Article 6(1)(f) GDPR).

3.5 IP addresses and security data

We read the IP address of requests to our Website and Service in order to apply rate limits and protect against abuse. For rate-limiting this IP address is used only transiently, as a key in our rate-limiting layer, and is not stored as a searchable record. The only place we store an IP address persistently is the waitlist record described in Section 3.3.

Purpose: security, abuse prevention and service integrity. Legal basis: our legitimate interest in the security of the Service (Article 6(1)(f) GDPR).

3.6 Website analytics

We measure aggregate, anonymous traffic to our Website using a cookieless analytics tool that does not set cookies, does not build individual profiles, and does not share personal data with third parties. Our use of cookies and similar technologies is described in our Cookie Policy.

Purpose: to understand overall Website usage and improve it. Legal basis: our legitimate interest in maintaining and improving the Website (Article 6(1)(f) GDPR).


4. Google user data

This section explains, in the terms required by the Google API Services User Data Policy, how we access, use, store and share data obtained from Google APIs. We request a single Google OAuth scope: https://www.googleapis.com/auth/business.manage. We request no other Google scope.

4.1 How we access Google user data

When you choose to connect your Google Business Profile, Google asks you to grant Recensio access under the business.manage scope. We use the resulting authorisation solely to read the reviews of the business you connect and to publish replies to those reviews on your instruction.

4.2 What we access and what we store

Through the Google Business Profile API we read, for each review: the review identifier, the reviewer's display name, the reviewer's profile photo URL, the star rating, the review text, the review's creation and update time, and any existing reply; and, at the level of the connected location, the total review count and the average rating.

Of this, we store in our database only: the review identifier, the reviewer's display name, the star rating and the review text (in the review record), and the average rating, review count and last-checked time (in the business record). The reviewer's profile photo URL, the review's creation and update time, and any existing reply are read to operate the Service but are not stored by us.

4.3 How we use Google user data

We use the review data to analyse each review and to draft and publish a reply in your business's tone of voice, according to your automation settings. We use it for no other purpose.

4.4 How we store and protect Google user data

Review data is stored in our EU-hosted database. The Google authorisation credential (the refresh token) is encrypted before it is stored, using AES-256-GCM encryption, with the encryption key held in a dedicated environment variable separate from the database. Access to the stored credential is restricted at the database level to our service role only.

4.5 How we share Google user data

To generate a reply, we send the reviewer's display name and the review text to our artificial-intelligence sub-processor, Anthropic, which processes them to produce the drafted reply and returns it to us. We do not log or retain the text of the prompt we send. Anthropic processes this data as our sub-processor under a data processing agreement and does not use it to train its models.

To notify you of a review that needs your approval, we also send the reviewer's display name, the rating, the review text and the drafted reply to our messaging sub-processor, so that you receive the approval notification.

Apart from the sub-processors listed in our Sub-processor List — each of which processes the data only to provide its service to us under a data processing agreement — we do not share Google user data with any third party, we never sell it, and we never use or transfer it for any purpose other than providing the Service.

4.6 Limited Use

Recensio's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train generalised or personalised artificial-intelligence or machine-learning models, we do not sell Google user data, and we do not transfer or use it for advertising, credit assessment or any purpose other than providing the Service.

4.7 Disconnecting Google

You can disconnect your Google Business Profile at any time from within the Service. When you disconnect, we send a revocation request to Google's OAuth revocation endpoint for your token, and we delete the stored credential from our database. If you delete an individual business or your whole account, the same revocation runs first; if the revocation cannot be completed, the deletion of that business does not proceed, so that no orphaned credential is left behind.


5. Artificial-intelligence processing

Replies are drafted by an artificial-intelligence model operated by our sub-processor Anthropic. To draft a reply we send to Anthropic the reviewer's display name, the review text, information about the business (its name, type, description and any custom instructions you have set), and examples of your previously approved replies so that the tone matches your business. We do not log or retain the prompt we send. Anthropic does not use data submitted through its API to train its models.

We do not carry out automated decision-making that produces legal effects concerning you, or that similarly significantly affects you, within the meaning of Article 22 GDPR. Where you have enabled automatic publishing, the model drafts and publishes replies according to the settings you have configured and expressly consented to; the terms governing that feature are set out in our Terms of Service.


6. Learning from your approved replies

To keep replies consistent with your voice, we store examples derived from your past replies (including your corrections to drafted replies). These examples are used only to serve the business they belong to. They are never pooled across customers, and they are never used to train any third-party or general model. This per-customer separation is a binding condition of the Service.


7. Profiling of reviewers

When we analyse a review, the model infers a small set of attributes about the review in order to adapt the reply. These attributes, stored in the review record, are: the register or tone of the review (for example enthusiastic, formal, minimal, standard or casual); whether a competitor or a staff member is mentioned; and behavioural indicators such as apparent customer type, visit frequency, likelihood of returning, and group type (for example a family). This profiling is limited to adapting the reply and has no legal or similarly significant effect on the reviewer.

The structured profile does not infer special categories of data (such as health, religion, sexual orientation or political opinion). However, the free text of a review, which is written by the reviewer and which we process to draft a reply, may contain such information if the reviewer chooses to reveal it — this can occur, for example, with businesses in a healthcare context. Where it does, that information is processed only to draft the reply and is subject to the safeguards in this Privacy Policy.

Because reviewers are not our customers and we usually have no means of contacting them directly, information required by Article 14 GDPR is provided through this publicly available Privacy Policy. We rely on the disproportionate-effort exception in Article 14(5)(b) GDPR. For this processing the controller is the business that owns the review, and its legal basis is its legitimate interest in managing its online reputation (Article 6(1)(f) GDPR); we act only as its processor.


8. Sub-processors and international transfers

We use third-party sub-processors to provide the Service, including for hosting, database, payments, messaging and email, error monitoring, and artificial-intelligence processing. Our current sub-processors, the data each receives and their locations, are listed in our Sub-processor List at https://recensio.ai/sub-processors.

Our hosting and database are located in the European Union (Frankfurt). Some of our sub-processors are established outside the European Economic Area, including in the United States. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses, or on an adequacy decision where one applies. You may request further information about these safeguards using the contact details in Section 13.


9. Data retention

We retain personal data for which we are the controller for as long as your account is active, and we delete it when you close your account, subject to any shorter period stated below or any longer period we are required by law to keep (for example accounting records). We do not currently operate an automated time-based deletion of account data; deletion takes place on account closure or on request.

We retain review data, for which we are a processor, for the duration of the relevant customer's relationship with us and until the customer deletes the business or the account, at which point the data is deleted as described in Section 10.

Waitlist data is retained until you ask us to remove it or until it is no longer needed for the purpose for which it was collected.


10. Deleting your account

You can delete your account and associated data from within the Service. When you do, we: revoke the Google authorisation for each connected business with Google; delete your customer record with our payments provider, Stripe; and delete your data across our systems, with related records removed by cascading deletion. A minimal record of the deletion is kept where necessary to demonstrate our compliance with data protection law.


11. Your rights

Under the GDPR you have the right to: access your personal data; have inaccurate data corrected; have your data erased; restrict or object to processing; data portability; and, where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights in relation to data for which we are the controller, contact us at support@recensio.ai. We will respond within one month, as required by Article 12(3) GDPR. Where the request concerns review data for which a business customer is the controller, we will direct you to, or assist, that customer.

You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Data Protection Commission of Ireland — Canal House, Station Road, Portarlington, Co. Laois, R32 AP23, Ireland; www.dataprotection.ie. You may also complain to the supervisory authority in the country where you live or work.


12. Security

We protect personal data with technical and organisational measures appropriate to the risk. These include EU-based hosting, encryption in transit, encryption at rest of the Google authorisation credential using AES-256-GCM, database-level access controls that restrict sensitive data to our service role, and error monitoring that does not receive the content of prompts. No method of transmission or storage is completely secure, but we work to protect your data and to review our measures over time.


13. Children

The Service is intended for use by businesses and is not directed to children. We do not knowingly collect personal data from children.


14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will change the "last updated" date at the top and, where changes are material, take reasonable steps to inform you. The version published on recensio.ai is the version in force.


15. Governing law and contact

This Privacy Policy and our processing of personal data are governed by Irish law and the GDPR.

For any question about this Privacy Policy or about how we handle your personal data, contact:

RECENSIO LIMITED Unit 2, 2 Bridge Street, Athlone, Co. Westmeath, N37 F1W4, Ireland Company registration number (CRO): 820098 Email: support@recensio.ai